{"schema_version":"1.9.0","id":"CVE-2025-3879","published":"2025-05-02T16:15:10.650Z","modified":"2026-08-12T03:51:48.049772551Z","aliases":["BIT-vault-2025-3879","GHSA-f9ch-h8j7-8jwg","GO-2025-3662"],"related":["openSUSE-SU-2025:15059-1"],"summary":"Vault’s Azure Authentication Method bound_location Restriction Could be Bypassed on Login","details":"Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hashicorp/vault","events":[{"introduced":"5dd7f25f5c4b541f2da62d70075b6f82771a650d"},{"fixed":"aa75903ec499b2236da9e7bbbfeb7fd16fa4fd9d"},{"introduced":"7eeafb6160d60ede73c1d95566b0c8ea54f3cb5a"},{"last_affected":"7eeafb6160d60ede73c1d95566b0c8ea54f3cb5a"}],"database_specific":{"cpe":["cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*","cpe:2.3:a:hashicorp:vault:1.19.0:*:*:*:enterprise:*:*:*"],"extracted_events":[{"introduced":"0.10.0"},{"fixed":"1.19.1"},{"introduced":"1.19.0"},{"last_affected":"1.19.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["1.19.0","v1.19.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3879.json"}}],"references":[{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2025-07-vault-s-azure-authentication-method-bound-location-restriction-could-be-bypassed-on-login/74716"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3879.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3879"},{"type":"PACKAGE","url":"https://github.com/hashicorp/vault"}],"database_specific":{"cna_assigner":"HashiCorp","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3879.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}